About The Position

CloudZero is seeking a Staff/Principal Software Engineer to lead the development of their Windows Endpoint Agent. This role involves taking a proof-of-concept Windows Filtering Platform callout driver and user-mode relay, and transforming it into a production-ready, signed, installable, and auto-updating product. The engineer will own the kernel-mode driver, user-mode service, signing and packaging, and ensure fail-open behavior to maintain customer network functionality. This is a critical role requiring deep Windows systems expertise, with a high bar for quality and ownership due to the potential impact of bugs on system stability and connectivity. The successful candidate will set the standard for future endpoint development.

Requirements

  • Deep Windows systems experience. You have shipped software that runs as a service, a driver, or an endpoint agent on Windows, not just applications on top of it.
  • Kernel-mode or low-level Windows development. KMDF or WDM, the Windows Driver Kit, and comfort debugging with WinDbg.
  • Working knowledge of Windows networking internals, the Windows Filtering Platform or a comparable traffic interception approach.
  • Proficiency in C or C++ for the driver side, in Go or another systems language for the user-mode side. You can read and reason about code in a language you did not write.
  • Comfort spanning the stack from a kernel driver to a desktop UI, or the self-awareness to say which end is your strength and where you will lean on the team.
  • Hands-on experience with Windows code signing and the realities of shipping a signed kernel driver, Authenticode, EV certificates, and Microsoft's attestation or WHQL process.
  • A track record of shipping endpoint software to machines you do not control, with the instinct to design for failure, cleanup, and least privilege.
  • The judgment to know when a kernel-level solution is worth it and when it is not, and the ability to explain that tradeoff to engineers, product, and leadership.
  • A track record of shipping, not just designing.

Nice To Haves

  • Built endpoint security, EDR, DLP, or network monitoring agents at enterprise scale.
  • Experience with TLS interception, MITM proxies, or certificate trust management.
  • Packaging and distribution experience with MSIX, MSI or WiX, or auto-update frameworks.
  • Familiarity with enterprise Windows deployment through Intune, MDM, or Group Policy.
  • Cross-platform endpoint experience spanning Windows and macOS.
  • You use AI coding tools in your own work and can describe your workflow and where they fail you.

Responsibilities

  • Take the Windows agent from proof of concept to a signed, installable, auto-updating product that runs on Windows.
  • Own the WFP callout driver (KMDF, C/C++) and the user-mode Go relay that reuses our shared capture core, and keep the two in lockstep as both evolve.
  • Solve production kernel-mode driver signing, EV certificate, Microsoft attestation, Secure Boot, without weakening code integrity on the customer's machine.
  • Build the installer, update, and clean uninstall path (MSI or MSIX), and the enterprise deployment story.
  • Design for fail-open. Non-AI traffic must never touch our code, and a driver or service failure must never break the endpoint.
  • Manage local CA trust and TLS interception, so it is safe, transparent, and fully reversible.
  • Build the endpoint client in Electron and TypeScript, and work directly with product on what the Windows agent exposes to the customer and where it needs to reach parity with macOS.
  • Raise the bar for the engineers around you through code review, design feedback, and direct mentorship.

Benefits

  • Collaborative, fast-moving environment
  • Work makes a direct impact
  • Values ownership, creativity, and curiosity
  • Tackling complex challenges in the cloud space
  • Working with cutting-edge technology
  • Driving meaningful outcomes
  • Growing with a company that’s scaling fast
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service